LensLlama

LensLlama Data Processing Agreement

Version 1.0 · Last updated: July 26, 2026

This Data Processing Agreement (“DPA”) is entered into between Foundry Lane LLC dba LensLlama (“LensLlama”, “we”, “our”, or “us”) and the entity that has agreed to LensLlama’s Terms of Service (“Customer”, “you”, or “your”). This DPA is incorporated by reference into and forms part of the Terms of Service between LensLlama and Customer.

This DPA reflects the parties’ agreement with respect to the Processing of Customer Data in connection with the LensLlama Service. It is effective upon Customer’s acceptance of the Terms of Service; customers who require an executed copy for procurement may request one (see “Executed versions” below).

1. Definitions

Capitalized terms not defined here have the meanings given in LensLlama’s Terms of Service.

  • “Customer Data”means any data, including Personal Data, that Customer or its end users submit to, or that is generated by, the LensLlama Service in connection with Customer’s use of the Service.
  • “Data Protection Laws”means all applicable laws and regulations relating to the Processing of Personal Data, including but not limited to the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and comparable state privacy laws in the United States.
  • “Personal Data”means any information relating to an identified or identifiable natural person, as defined under applicable Data Protection Laws. Because LensLlama’s architecture is designed to exclude patient identifiers, Personal Data under this DPA primarily refers to business contact information (name, business email, business address, phone) of Customer’s authorized users, and does not include patient information.
  • “Processing”(and “Process”) means any operation performed on Personal Data, whether or not by automated means, including collection, storage, use, disclosure, transmission, and deletion.
  • “Processor” means the entity that Processes Personal Data on behalf of the Controller.
  • “Controller” means the entity that determines the purposes and means of the Processing of Personal Data.
  • “Subprocessor” means any third party engaged by LensLlama to Process Personal Data on behalf of Customer.
  • “Security Incident” means any confirmed unauthorized access to, disclosure of, alteration of, or destruction of Personal Data that compromises the confidentiality, integrity, or availability of that data.

2. Roles and Scope

2.1 Roles. For purposes of this DPA and applicable Data Protection Laws: Customer is the Controller of Personal Data submitted to or Processed by the Service, and LensLlama is the Processorof Personal Data on behalf of Customer, acting solely on Customer’s documented instructions as set forth in the Terms of Service and this DPA.

2.2 Scope of Processing. LensLlama will Process Personal Data only to provide, maintain, and support the Service; to comply with reasonable documented instructions from Customer that are consistent with the Terms of Service; to comply with applicable law; and as otherwise permitted or required by this DPA.

2.3 Nature and purpose of Processing. LensLlama Processes Personal Data solely to provide the Service — an online platform connecting eyecare practices with optical laboratories. Processing activities include account provisioning, authentication, order intake and routing, payment processing (via Subprocessors), shipping label generation (via Subprocessors), customer support, and Service analytics.

2.4 Categories of data.Personal Data Processed under this DPA is limited to business contact information of Customer’s authorized users, order metadata (opaque order identifiers, lens specifications, business shipping addresses), and Service usage information. LensLlama does not collect, receive, or Process patient identifiers of any kind. No patient names, dates of birth, medical record numbers, chart numbers, patient contact information, insurance information, or other patient identifiers are stored, transmitted, or accepted by the Service.

2.5 Data subjects.Data subjects are Customer’s authorized users of the Service (employees, contractors, or agents of Customer’s business).

3. Customer Responsibilities

3.1 Lawful basis. Customer represents and warrants that its provision of Personal Data to LensLlama and the Processing performed by LensLlama under this DPA comply with all applicable Data Protection Laws, including that Customer has provided all necessary notices and obtained all necessary consents.

3.2 Prohibited data.Customer agrees not to submit patient identifiers or other Protected Health Information (as defined under the U.S. Health Insurance Portability and Accountability Act, “HIPAA”) to the Service. LensLlama’s Service is architecturally designed to exclude such information, and the Terms of Service prohibit its submission.

3.3 Documented instructions.Customer’s use of the Service in accordance with the Terms of Service constitutes Customer’s complete and documented instructions to LensLlama for the Processing of Personal Data.

4. LensLlama Obligations

4.1 Compliance with instructions.LensLlama will Process Personal Data only in accordance with Customer’s documented instructions and applicable law. LensLlama will inform Customer if, in its opinion, an instruction violates applicable Data Protection Laws.

4.2 Confidentiality. LensLlama will ensure that persons authorized to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.3 Security. LensLlama will implement and maintain appropriate technical and organizational measures to protect Personal Data as described in Schedule A (Security Measures) below.

4.4 Assistance.LensLlama will provide reasonable assistance to Customer in fulfilling Customer’s obligations to respond to data subject requests, conduct data protection impact assessments, and cooperate with supervisory authorities, in each case at Customer’s expense to the extent such assistance requires resources beyond LensLlama’s standard Service support.

5. Data Subject Rights

5.1 Assistance with requests.Taking into account the nature of the Processing, LensLlama will assist Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer’s obligation to respond to requests from data subjects seeking to exercise their rights under applicable Data Protection Laws (including rights of access, correction, deletion, portability, and opt-out).

5.2 Direct requests. If LensLlama receives a request directly from a data subject, LensLlama will promptly notify Customer of the request, and will not respond to the request directly except to acknowledge receipt and direct the data subject to Customer, unless legally required to do so.

5.3 CCPA/CPRA specific rights.For California residents, Customer’s authorized users may exercise rights of access, deletion, correction, portability, and opt-out of sale as described in LensLlama’s Privacy Policy. LensLlama does not sell Personal Data.

6. Subprocessors

6.1 Authorized Subprocessors. Customer authorizes LensLlama to engage the Subprocessors listed in Schedule B (Subprocessor List) below to Process Personal Data in connection with the Service.

6.2 Subprocessor obligations. LensLlama will enter into a written agreement with each Subprocessor imposing data protection obligations substantially similar to those set out in this DPA, and will remain liable for the acts and omissions of its Subprocessors to the same extent as if performed by LensLlama itself.

6.3 Notification of changes.LensLlama will notify Customer at least thirty (30) days in advance of engaging a new Subprocessor or replacing an existing Subprocessor, by posting an updated Schedule B on LensLlama’s website or via written notice (email is acceptable).

6.4 Objection right. If Customer objects in writing to a proposed new Subprocessor within thirty (30) days of notification on reasonable grounds relating to the protection of Personal Data, the parties will discuss the objection in good faith. If the parties cannot reach a mutually acceptable resolution, Customer may terminate the affected portion of the Service without penalty, subject to a pro-rata refund of any prepaid fees for the terminated Service.

7. Data Transfers

7.1 US-only Processing. LensLlama and its Subprocessors Process Personal Data solely within the United States. LensLlama does not transfer Personal Data outside the United States.

7.2 Future changes. If LensLlama at a future date proposes to Process Personal Data outside the United States, it will provide Customer with prior written notice and, if legally required, execute appropriate transfer mechanisms before initiating such Processing.

8. Security Incidents

8.1 Notification.LensLlama will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting Customer’s Personal Data.

8.2 Contents of notice. The notification will include, to the extent known at the time, a description of the nature of the Security Incident (including the categories and approximate number of data subjects and records affected), the likely consequences of the Security Incident, and the measures LensLlama has taken or proposes to take to address it, including measures to mitigate its possible adverse effects.

8.3 Cooperation.LensLlama will reasonably cooperate with Customer in Customer’s investigation and remediation of the Security Incident, at Customer’s expense to the extent such cooperation requires resources beyond LensLlama’s standard Service support.

8.4 No admission. Notification of a Security Incident under this DPA is not, and will not be construed as, an admission of fault or liability by LensLlama.

9. Audit Rights

9.1 Documentation.LensLlama will make available to Customer, on written request no more than once per twelve (12) month period, information reasonably necessary to demonstrate LensLlama’s compliance with this DPA, including summary information regarding LensLlama’s security controls, Subprocessor list, and any relevant third-party audit reports (e.g., SOC 2 reports if and when available).

9.2 On-site audits.If Customer reasonably believes that documentation provided under Section 9.1 is insufficient, Customer may request an on-site audit of LensLlama’s Processing operations, subject to the following conditions: the audit occurs no more than once per twelve (12) month period (except in the case of a Security Incident); reasonable advance written notice (at least thirty (30) days); the audit is conducted during normal business hours in a manner that does not unreasonably interfere with LensLlama’s operations; the auditor is a mutually agreed independent third party bound by confidentiality obligations; and Customer bears the cost of the audit, unless the audit reveals material non-compliance by LensLlama, in which case LensLlama will reimburse reasonable audit costs.

10. Return and Deletion of Data

10.1 Deletion on termination.Upon termination or expiration of Customer’s subscription to the Service, LensLlama will delete or return all Personal Data Processed on Customer’s behalf within sixty (60) days, unless applicable law requires retention.

10.2 Data export. Prior to deletion, Customer may export order history and other Customer Data through Service-provided export functionality or, if such functionality is not available, by written request to LensLlama.

10.3 Retained data. LensLlama may retain Personal Data to the extent required by applicable law (e.g., tax records, payment transaction records, records required for defense of legal claims), for the minimum period required and subject to continued confidentiality and security obligations.

11. Liability and Indemnification

The parties’ respective liability under this DPA is governed by the limitations of liability set forth in the Terms of Service. This DPA does not create additional liability beyond that provided in the Terms of Service.

12. Term and Termination

12.1 Term.This DPA is effective as of the Effective Date and continues for the duration of Customer’s subscription to the Service, plus any period during which LensLlama continues to Process Personal Data on Customer’s behalf pursuant to Section 10.

12.2 Survival. Sections 8 (Security Incidents), 9 (Audit Rights), 10 (Return and Deletion of Data), 11 (Liability), and 13 (Governing Law) survive termination of this DPA.

13. Governing Law and Miscellaneous

13.1 Governing law. This DPA is governed by the laws of the State of California, without regard to conflict of laws principles.

13.2 Dispute resolution. Any dispute arising under this DPA is subject to the dispute resolution provisions of the Terms of Service.

13.3 Order of precedence. If there is a conflict between this DPA and the Terms of Service, this DPA controls with respect to the Processing of Personal Data. If there is a conflict between this DPA and any other agreement between the parties, this DPA controls with respect to the Processing of Personal Data unless the other agreement is executed after this DPA and expressly supersedes this DPA.

13.4 Entire agreement. This DPA (together with the Terms of Service) constitutes the entire agreement between the parties with respect to the Processing of Personal Data and supersedes any prior agreements or understandings on the same subject matter.

13.5 Amendments.LensLlama may update this DPA from time to time by posting an updated version on its website. Material changes will be notified to Customer at least thirty (30) days in advance. Customer’s continued use of the Service after the effective date of an updated DPA constitutes acceptance of the updated DPA.

Schedule ASecurity Measures

LensLlama implements and maintains the following technical and organizational security measures to protect Personal Data:

A.1 Access controls.

  • Role-Based Access Control (RBAC) with deny-by-default authorization
  • Organization-scoped data access (Customer’s data is isolated by organization identifier)
  • Passwordless authentication via magic-link email (no shared passwords, no password database)
  • Multi-factor authentication mechanisms available

A.2 Encryption.

  • Data at rest encrypted using industry-standard mechanisms (currently Fly.io Postgres default encryption)
  • Data in transit encrypted via TLS 1.2 or higher

A.3 Architectural safeguards.

  • No patient identifiers architecture: the Service is designed to exclude patient names, dates of birth, medical record numbers, chart numbers, patient contact information, insurance information, and other patient identifiers. Structured input controls (dropdowns, enums) minimize free-text patient-data leak risk.
  • Opaque order identifiers (LL-XXXXXX format) with no embedded patient information
  • Pattern-validated text fields reject inputs that resemble patient identifiers

A.4 Audit and logging.

  • Comprehensive audit logging on every data mutation
  • Fail-closed audit design (the Service does not proceed if audit logging fails)
  • Logs retained per data retention policy

A.5 Operational security.

  • Least-privilege access for LensLlama personnel
  • Confidentiality obligations for all personnel with access to Personal Data
  • Regular security review of Subprocessor practices
  • Incident response procedures for Security Incidents

A.6 Continuous improvement.

  • Security measures are reviewed and updated as the Service evolves and as new threats or best practices emerge
  • Third-party security assessments (e.g., SOC 2) may be pursued as LensLlama scales

Schedule BSubprocessor List

LensLlama engages the following Subprocessors to Process Personal Data in connection with the Service. All Subprocessors are located in the United States.

SubprocessorPurposeData Categories Processed
Fly.ioApplication hosting, database hostingAll Customer Data (hosted infrastructure)
Stripe, Inc.Payment processing (subscriptions + destination charges)Payment method information, billing address, transaction records
ResendTransactional email delivery (sign-in links, order notifications, referral notifications)Business email addresses, email content metadata
ShippoShipping label generation, carrier account integrationBusiness shipping addresses, package metadata
Cloudflare, Inc.DNS management, edge network servicesIP addresses, request metadata (transient)

Changes to this Subprocessor list are governed by Section 6 of this DPA. Customer will be notified of proposed changes at least thirty (30) days in advance.

Executed versions

This DPA is deemed accepted upon Customer’s acceptance of the Terms of Service. Customers who require an executed copy for procurement (e.g., a signed vendor agreement) may request one by emailing contact@lensllama.net; the parties may execute this DPA via electronic signature.

See also our Terms of Service, Privacy Policy, and Trust page.